CUSTOMER PRIVACY POLICY


TABLE OF CONTENTS

  1. WHO ARE WE
  2. PROCESSING OF YOUR PERSONAL DATA
  3. PROCESSING OF PERSONAL DATA ON YOUR BEHALF
  4. TRANSFER OF PERSONAL DATA
  5. SECURITY & CONFIDENTIALITY
  6. WEBSITE & COOKIES
  7. SOCIAL MEDIA
  8. EXERCISING YOUR RIGHTS
  9. DATA PROTECTION AUTHORITY

PRIVACY POLICY


 
1.WHO ARE WE

We are Confiva Global d.o.o. residing at Stegne 13A 1000 Ljubljana Slovenia with company registration number SI8827451000.

We care about your privacy and every time we deal with your personal data we do so in accordance with the provisions of the general data protection regulation and the national law relating to the processing of personal data.

We are required under data protection legislation to make the information contained in this privacy policy accessible to you. This privacy policy sets out which measures are taken to protect your privacy when using our services or products, and what rights you have in this respect.

When processing your personal data we are in most cases the “data controller”. This means that we determine the purpose and means of the processing.

By using our services and/or products, you agree to the collection and processing of some of your personal data in accordance with the purpose described in our privacy policy. You are invited to read this privacy policy carefully and familiarise yourself with its content. Marko Šček is our Privacy Coordinator and you can reach them at [email protected]fiva.com for any questions or to exercise your rights. Future amendments to this policy cannot be excluded. We, therefore, ask that you read the privacy policy from time to time.

2. PROCESSING OF YOUR PERSONAL DATA

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). We try to collect as little personal information as possible in order to achieve our goals.

We comply with data protection laws which require that the personal information we process about you must be:

    • Collected only for valid purpose(s) that we have clearly explained to you.
    • Used lawfully, fairly and in a transparent way which means in a way that is relevant to the purpose(s) we informed you about, limited only to those purpose(s) and in no way incompatible with those purpose(s).
    • Accurate and kept up to date, kept only as long as necessary for the purpose(s) we have told you about and handled securely.

We may request certain information from you in order to enable you to use or purchase our services or products. If have processes in place to obtain your personal information in a different way, we will state this in this privacy policy. If you have any questions do contact our privacy coordinator.

More specifically we will collect any or all of the following data elements:

    • Correspondence content Customer name
    • Date & time
    • Electronic identification data Email address
    • Essential cookies Home address
    • Images from security camera
    • Payment balance data
    • Personal email address
    • Phone number
    • Pictures / images
    • Profile preferences
    • Third-party cookies

We rely on you to provide us with correct data. If the data changes, we invite you to let us know, so we can keep the data up to date.

We process the data to allow us to deliver the services/products and to continually improve the services/products available to you and adapt them to your needs. More specifically we perform the below processing:

Customer appointments
    • Description: Register customer appointments either on paper or on a computer
    • Purpose: To manage availability and calendar Legal basis: Contract
    • Retention period: As from termination of the contract, retention during the legal period and/or period relevant for legal action
    • Data categories: Date & time, Customer name Data is processed in the EU
Customer correspondence
    • Description: communication with customers in electronic or paper form Purpose: To provide proper service to the client
    • Legal basis: Contract
    • Retention period: As from termination of the contract, retention during the legal period and/or period relevant for legal action
    • Data categories: Correspondence content, Personal email address, Customer name Data is processed in the EU
Corporate website
    • Description: Corporate website for consultation by the client or prospective client Purpose: To inform client or prospective client
    • Legal basis: Legitimate interests
    • Retention period: As from termination of the contract, retention during the legal period and/or period relevant for legal action
    • Data categories: Third-party cookies, Phone number, Email address, Electronic identification data, Essential cookies, Customer name
    • Data is processed in the EU
Online event platform
    • Description: Processing of data as part of people’s participation in online events. This might include live video streams, opportunity for online networking through chat and video, online polls, etc.
    • Purpose: To host online events Legal basis: Contract
    • Retention period: As from termination of the contract, retention during the legal period and/or period relevant for legal action
    • Data categories: Email address, Profile preferences, Correspondence content, Pictures / images, Customer name
    • Data is processed in the EU
Customer invoicing & accounting
    • Description: Calculating the fee owed, sending out invoices and ensuring payment Purpose: To ensure proper payment
    • Legal basis: Contract
    • Retention period: As from termination of the contract, retention during the legal period and/or period relevant for legal action
    • Data categories: Home address, Payment balance data, Customer name Data is processed in the EU
Security camera
    • Description: Capturing and / or storing of security images or video Purpose: To ensure security, prevent fraud or theft…
    • Legal basis: Legitimate interests
    • Retention period: Maximum 4 weeks, unless in case of evidence of the incident: until the incident has been handled
    • Data categories: Images from security camera, Date & time Data is processed in the EU

In the above processing, we are the data controller.

Where you provided consent, you have the right to revoke it. You have the right to withdraw your consent at any time.

In case you object to the processing of your data, please contact us so we can evaluate together if a contractual relationship is possible and a continuation of the use of our services is possible.

We also handle supplier data. When we collect, process and store supplier data, we want to make sure we only collect, process and store data we really need and are entitled to handle in this way. In dealing with our suppliers we typically collect, process and store the name, work email and work phone of the person(s) interacting with us. We also collect, process and store the VAT number of our suppliers. If we provide parking space or access to our business area to suppliers’ vehicles, we might collect, process and store the licence plate number and timing of the visit for purposes of organisation and security. Our security measures are functionally and technically in line with industry best practices. We retain the information during the legal period and/or period relevant for legal action.

3. PROCESSING OF PERSONAL DATA ON YOUR BEHALF

The specific nature of our relationship makes it unlikely that we will process other people’s personal data on your behalf. In the exceptional case that this nevertheless occurs, we are the processor and you are the controller. We will then carry out your instructions for the processing, possible subcontracting, the fate of the data at the end of the agreement and the possible transfer of data. We will therefore take the necessary security measures and assist you in fulfilling your obligations under the GDPR.

4. TRANSFER OF PERSONAL DATA

In order to provide certain services or products, we might work with third parties such as IT partners, insurance partners, accounting partners, and legal advisors. More specifically we reserve the right to transfer your personal data to our partners.

    • IT Support
      Data items: Customer name, Electronic identification data, Email address
      Data is processed in the EU
      Amazon EU companies act as the data processor
  •  
    • Communication services
      Data items: Electronic identification data, Pictures / images
      Data is processed in the EU
      Twilio Ireland Limited acts as the data processor
  •  
    • Communication Services
      Data items: Electronic identification data, Pictures / images
      Data is processed in the EU
      Whereby AS acts as the data processor
  •  
    • Video streaming hosting
      Data items: Electronic identification data, Pictures / images
      Data is processed in the EU
      MUX UK Ltd acts as the data processor
  •  
    • Email delivery service
      Data items: Customer name, Electronic identification data, Correspondence content, Email address
      Data is processed in the EU
      Mailjet SAS acts as the data processor
  •  
    • Sociale media – Linkedin
      Data items: Staff member name, Electronic identification data, Pictures / images, Involved
      party name, Date & time, Electronic localisation data
      Data is processed in the EU
      LinkedIn Ireland Unlimited Company acts as the data processor
  •  
    • Social media – Facebook / Instagram
      Data items: Customer name, Electronic identification data, Pictures / images, Date & time,
      Electronic localisation data
      Data is processed in the EU
      META PLATFORMS IRELAND LIMITED (ex-Facebook) acts as the data processor
  •  
    • Website analytics & visitor statistics
      Data items: Electronic identification data, Date & time, Third-party cookies, Performance cookies, Electronic localisation data
      Data is processed in the EU
      Google Ireland Limited acts as the data processor

If we receive personal data from a third party referring you to us, we assume this data is obtained directly from you or with your consent. If this is not the case, please advise us immediately.

These third parties will generally act as the data processor. Please do note that social media platforms, commerce platforms and structural sales partners are often regarded as joint controllers. If you participate in an online call, meeting, conference,… do note that any data you choose to share will be visible and/or audible to the other participants. Please consider this before sharing your personal details, video, audio or any other data. In case you object to the transfer of your data, please contact us so we can evaluate together if a contractual relation is possible and a continuation of the use of our services is possible. Please do note that we may be required by law to process certain data and, as the case may be, to transmit them to the relevant authorities. As this is a legal obligation you can not object to this transfer.

5. SECURITY & CONFIDENTIALITY

We undertake to keep your personal data secure & confidential and have established security procedures to avoid any loss, abuse or alteration to this personal data in line with industry best practices.

6. WEBSITE & COOKIES

Navigation on our website may result in cookies being saved to your computer. They simplify the visit and improve your experience. When visiting our website you will be informed of the cookies being used and we will ask you for your consent. Furthermore, each time you visit our website, the web server automatically processes your IP address and/or your domain name. We may publish links to websites owned and operated by third parties. If you click on such a link you will navigate to another website. Please make sure you read and understand the privacy policy of that website, as it may differ from our policy and is outside of our control. If you feel unsure or cannot agree with the policy, we suggest you leave that website.

7. SOCIAL MEDIA

If you use the social media functions such as eg “like” or “share” button that may be on our website, or if you visit our social media page, please know that your personal data will be processed by the social media platform. In this processing, the European regulator considers us and the social media platform both to be joint data controllers, which means that we jointly determine why and how your personal data is processed. You can find out how we process your personal data in this privacy statement. You can find information about the processing by the relevant social media platform in their privacy statement. We ask you to read the privacy statement of the social media platform carefully before visiting the social media items on ourpage or our page on the social media platform.

If we hold an event such as a client network event, opening event, premiere etc. we might have photographers or videographers present. The photos and videos they shoot are purposed to be used in marketing materials and / or published on our social media pages. When you are not the main subject of these materials the data protection authority’s guidance is that your GDPR explicit consent is not required. However, should you oppose to us using materials where you are depicted, please let us know.

8. EXERCISING YOUR RIGHTS

In accordance with the general data protection regulation you have the right to:

    • Request access to your personal information (commonly known as a “data subject access request”). This enables you to receive a copy of the personal information we hold about you.
    • Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected. Request erasure of your personal information. This enables you to ask us to remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to remove your personal information where you have exercised your right to object to processing (see below).
    • Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes.
    • Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example, if you want us to establish its accuracy or the reason for processing it.
    • Withdraw your prior consent to processing at any time.
    • The right to object to a decision based solely on automated processing, including profiling.
    • The right to receive your personal data in a structured, commonly used and machine-readable format and have transmitted those data to another controller.

We sometimes need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.

You can exercise your rights by contacting our Privacy Coordinator Marko Šček via [email protected] or at the below company address:

Confiva Global d.o.o.
c/o Marko Šček
Stegne 13A 1000 Ljubljana Slovenia

9. DATA PROTECTION AUTHORITY

You can direct any complaints and comments to the competent data protection authority at the
below address:
Information Commissioner
Dunajska cesta 22
1000 Ljubljana, Slovenia
https://www.ip-rs.si

  •